CVE-2011-1484
published 2011-07-27CVE-2011-1484: jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.29%
81.2th percentile
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
| redhat | jboss_seam_2_framework | <= 2.2.2 | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JBoss Seam EL interpolation in exception handling
vendor_redhat·2011-07-18·CVSS 6.8
CVE-2011-2196 [MEDIUM] JBoss Seam EL interpolation in exception handling
JBoss Seam EL interpolation in exception handling
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.
Red Hat
JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
vendor_redhat·2011-04-20·CVSS 6.8
CVE-2011-1484 [MEDIUM] JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
GHSA
GHSA-x438-vrwx-gvfx: jboss-seam
ghsa_unreviewed·2022-05-17
CVE-2011-1484 [MEDIUM] GHSA-x438-vrwx-gvfx: jboss-seam
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
GHSA
GHSA-6m4p-jvxh-733r: jboss-seam
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-2196 [MEDIUM] GHSA-6m4p-jvxh-733r: jboss-seam
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2196 JBoss Seam EL interpolation in exception handling
bugzilla·2011-06-10·CVSS 6.8
CVE-2011-2196 [MEDIUM] CVE-2011-2196 JBoss Seam EL interpolation in exception handling
CVE-2011-2196 JBoss Seam EL interpolation in exception handling
Acknowledgements:
Red Hat would like to thank the ObjectWorks+ Development Team at Nomura Research Institute for reporting this issue.
Discussion:
It was found that the fix for CVE-2011-1484 was incomplete: JBoss Seam 2 did not block access to all malicious JBoss Expression Language (EL) constructs in page exception handling, allowing arbitrary Java methods to be executed. A remote attacker could use this flaw to execute arbitrary code via a specially-crafted URL provided to certain applications based on the JBoss Seam 2 framework.
Note: A properly configured and enabled Java Security Manager would prevent exploitation of this flaw.
---
This issue has been addressed in following products:
JBEAP 5 for RHEL 6
Via RHSA-2
Bugzilla
CVE-2011-1484 JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
bugzilla·2011-03-31·CVSS 6.8
CVE-2011-1484 [MEDIUM] CVE-2011-1484 JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
CVE-2011-1484 JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
JBoss Seam2 does not properly block access to EL constructs in page exception handling. This allowed arbitrary Java methods to be executed. A remote attacker could use this flaw to execute arbitrary code via a URL, containing appended, specially-crafted expression language parameters, provided to certain applications based on the JBoss Seam framework.
Note: A properly configured and enabled Java Security Manager would prevent exploitation of this flaw.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 5
JBEAP 4.3.0 for RHEL 4
Via RHSA-2011:0460 https://rhn.redhat.com/errata/RHSA-2011-0460.html
---
This issue has been addressed in following products:
JBEAP 5
http://www.redhat.com/support/errata/RHSA-2011-0460.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0461.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0462.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0463.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1148.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1251.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=692421https://docs.redhat.com/docs/en-US/JBoss_Communications_Platform/5.1/html/5.1.1_Release_Notes/ar01s05.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0460.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0461.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0462.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0463.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1148.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1251.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=692421https://docs.redhat.com/docs/en-US/JBoss_Communications_Platform/5.1/html/5.1.1_Release_Notes/ar01s05.html
2011-07-27
Published